PT-2020-4595 · Marketo · Marketo Sales Insight Plugin

Published

2020-10-20

·

Updated

2020-10-22

·

CVE-2020-24416

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Marketo Sales Insight plugin version 1.4355 and earlier
Description The issue is related to a blind stored Cross-Site Scripting (XSS) vulnerability. This could allow an attacker to inject malicious scripts into vulnerable form fields. When a victim browses to the page containing the vulnerable field, malicious JavaScript may be executed in their browser. The vulnerability is also associated with a lack of input data sanitization, which could enable a remote attacker to execute arbitrary JavaScript code.
Recommendations For Marketo Sales Insight plugin version 1.4355 and earlier, update to a version that addresses the input data sanitization issue and fixes the blind stored Cross-Site Scripting (XSS) vulnerability. As a temporary workaround, consider restricting access to vulnerable form fields to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05144
CVE-2020-24416

Affected Products

Marketo Sales Insight Plugin